From a28d76e7d0ba64ef9c35885f4e648420f99ac0ec Mon Sep 17 00:00:00 2001 From: Avi Date: Fri, 18 Sep 2026 21:03:08 -0500 Subject: [PATCH] =?UTF-8?q?checkpoint:=20sync=20to=2021c522b=20=E2=80=94?= =?UTF-8?q?=20durable=20pairing=20trace=20log,=20forensics=20hygiene=20(20?= =?UTF-8?q?26-09-18)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- CHECKPOINT-encryption.md | 68 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 68 insertions(+) diff --git a/CHECKPOINT-encryption.md b/CHECKPOINT-encryption.md index 2fd813d..68a0a49 100644 --- a/CHECKPOINT-encryption.md +++ b/CHECKPOINT-encryption.md @@ -1,3 +1,71 @@ +# Checkpoint — durable pairing trace log + forensics-file hygiene (2026-09-18) + +## Where things are +- Project: `/home/avi/Projects/Keynctr` +- Branch: `master` @ **`21c522b`** ("chore(pairing): durable trace log + keep + e2e loopback traffic out of forensics files"). Previous feature HEADs: + `188b2eb`, `aedde8f`, `759b5dd`, `5aa122d`, `f59c2b1`. +- Working tree: clean for tracked files. Untracked intentionally NOT + committed: `COSMIC_THEME.md`, `KeynectrAppIconPossibility02.jpeg`, + `deferred/` (stays deferred). +- Release binary rebuilt at `21c522b` (2026-09-18 ~21:00) — Electron spawns + this one. **No live Amber scan has run against `188b2eb` or `21c522b` + yet**: the capture file shows no real scan since Sep 16 21:03. +- Verification (all green at `21c522b`): `cargo fmt --check` clean, + `cargo test` **208 unit + 2 e2e passed / 0 failed**, `cargo clippy + --all-targets` 0 warnings, `cargo build --release` green. Frontend: + `npm test` **116 passed**, `npm run typecheck` / `lint` / + `format:check` / `build` / `electron:build` all clean. + +## What was completed since the last checkpoint +- **Forensics contamination found and fixed**: pairing-capture.jsonl had + grown two new lines (Sep 18 20:08 + 20:42) that were NOT Amber — they were + the e2e harness's fake-scanner events, appended because the capture path + was hardcoded and the loopback e2e test pairs through the same + `run_pairing_task`. Removed the two test events from the capture file + (backup: `pairing-capture.jsonl.bak-20260918`); loopback pairings now skip + the capture file and the pairing-session trace lines entirely (the + session-level `identity adopted` / `session failed` lines are shared with + the bunker flow and can still include a labelled e2e entry — distinguish + by the loopback relay set in the preceding `pairing started` line, which + real sessions never have). +- **Durable pairing trace (`pairing-trace.log`)**: every pairing decision + point now appends a timestamped line to + `~/Tools/keynctr-debug/pairing-trace.log` — pairing started (ephemeral key + + relay set), inbound 24133, decrypt failure (real NIP-44 error), + not-a-request (exact payload), pre-handshake method, connect answered, + identity adopted (npub), session failed (reason). Backend stderr only + reaches the Electron console and /tmp gets cleaned, so previously a failed + live handshake left NO durable trace. Verified working: the e2e run after + the change wrote `identity adopted ... CONNECTED` lines proving the trace + path end-to-end. + +## Commits added (newest first) +- `21c522b` chore(pairing): durable trace log + keep e2e loopback traffic + out of forensics files + +## How to reproduce / exercise +- Dev loop (unchanged): `npx vite --port 5173` in `frontend/` FIRST, then + `NOSTR_GUI_DEV_URL=http://localhost:5173 KEYNCTR_ENABLE_GPU=1 npx electron .`. +- GUI: Signer mode -> "Show QR" -> scan in Amber -> approve. After the scan + (success OR failure), read `~/Tools/keynctr-debug/pairing-trace.log` — the + last lines name exactly where the handshake stopped. Raw frames still + append to `pairing-capture.jsonl` (live pairings only now). + +## Outstanding / next steps +1. **Live Amber re-scan still required** — nothing has exercised the + `188b2eb` lenient parser against real Amber traffic yet. The trace log + will show, without any terminal capture, whether the connect arrives, + decrypts, parses, and how far the handshake gets. +2. If trace shows `pre-handshake 'get_public_key' ignored`, relax the + connect-only gate (the log line names it outright). +3. `publish_profile_metadata` (kind 0) still signs locally — reroute + through `Signing` for external profiles (P2). +4. Step 5 (KDF upgrade), Step 6 (undo preserves ProfileSummary), Step 7 + (rename pass incl. `homepage` URL). + +--- + # Checkpoint — Amber pairing: lenient NIP-46 payload parse + real decrypt-error logging (2026-09-16) ## Where things are